Files
supabase/apps/www/components
312d05af4b fix(www): changelog frontmatter (#48249)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Security/bug fix

## What is the current behavior?

The changelog entry parser exposes all YAML frontmatter fields parsed by
`matter()` directly to the client via Next.js props. This includes
private fields like `internal:` (escalation teams, notes) and
`reviewers:`, which get serialized into the page's `__NEXT_DATA__` and
are visible in View Source even if never rendered.

## What is the new behavior?

- Added `PUBLIC_FRONTMATTER_KEYS` constant that explicitly allowlists
only the fields safe to expose to the browser
- Added `toPublicFrontmatter()` function that filters frontmatter down
to the allowlist, dropping `internal:`, `reviewers:`, and any other
private keys
- Updated `parseChangelogEntryFile()` to apply the allowlist before
returning frontmatter to callers
- Added comprehensive unit tests covering both the filtering logic and
the integration with the parser

This uses an allowlist approach rather than a denylist, so new private
fields added upstream won't silently leak to clients.

## Additional context

The allowlist is kept in sync with `ChangelogEntryFrontmatter` in
`changelog-repo.ts` per the code comment. Tests verify that:
- Only allowlisted keys are present in the returned frontmatter
- Private fields like `internal` and `reviewers` are never exposed
- Public fields flow through untouched
- Undefined values are omitted from the result

https://claude.ai/code/session_017uSmnCLsskFYR7YH8DKGkr

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added a shared changelog title renderer that safely displays titles as
inline Markdown.
* Added plain-text title extraction for consistent headings and SEO
metadata.
* **Bug Fixes**
* Prevented private/internal changelog frontmatter (including reviewer
metadata) from being exposed to browser-rendered pages.
* Ensured featured and non-featured changelog timelines stay consistent
even when some entries fail to serialize.
* Improved the changelog detail not-found behavior to revalidate instead
of caching 404s indefinitely.
* **Tests**
* Added coverage for public frontmatter allowlisting, date normalization
(`publish_date`/sorting), and `sortDate` consistency across YAML
variations.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Lukas Bernert <lukas@bernert.at>
2026-07-23 08:26:01 -07:00
..
2024-10-07 09:47:32 +02:00
2026-07-03 15:00:43 +10:00
2026-07-01 12:13:15 +00:00
2026-07-03 15:00:43 +10:00
2024-09-17 11:07:38 +02:00
2026-07-03 15:00:43 +10:00
2025-09-03 14:49:28 +02:00
2024-04-10 11:51:26 +02:00
2026-06-26 15:47:52 +02:00
2026-07-03 15:00:43 +10:00
2026-07-03 15:00:43 +10:00
2024-04-19 16:24:21 +02:00
2026-06-30 10:28:17 +02:00
2026-06-30 10:28:17 +02:00
2026-07-03 15:00:43 +10:00